MEDIUM
Entity Browser Project
CVE published 2026-09-02
CVE-2026-18986
A Cross-site Scripting (XSS) vulnerability exists in Entity Browser versions from 0.0.0 to 2.16.0 due to improper neutralization of input during web page generation. This issue allows stored XSS attacks. The vulnerability impacts Drupal installations using Entity Browser, allowing attackers to inject malicious scripts. Defenders should assess exposure and prioritize patching or mitigation to prevent poten [truncated]